CVE-2020-1178
published 2020-06-09CVE-2020-1178: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.13%
86.4th percentile
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka 'Microsoft SharePoint Server Elevation of Privilege Vulnerability'.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server | — | — |
| microsoft | microsoft_sharepoint_enterprise_server | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | microsoft_sharepoint_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability class is Server-Side Request Forgery (SSRF) via a specially crafted authentication request to SharePoint Server, leading to elevation of privilege in the SharePoint application pool account context. ↗
- →Attack requires an authenticated attacker to create a specially crafted page that triggers a server-side request, then sends a crafted message to perform SSRF. Monitor SharePoint authentication requests and server-side outbound connections originating from the SharePoint application pool. ↗
- →The Preview Pane is NOT an attack vector for this vulnerability; focus detection on direct authentication request handling rather than preview rendering. ↗
- ·Exploitation requires an authenticated attacker; unauthenticated exploitation is not possible for this vulnerability. ↗
- ·As of the advisory, the vulnerability has not been publicly disclosed or exploited in the wild; exploitation is rated 'Less Likely' for both latest and older software releases. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Server Elevation of Privilege Vulnerability
vendor_msrc·2020-06-09·CVSS 8.8
CVE-2020-1178 [HIGH] Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server. An attacker who successfully exploited this vulnerability could execute malicious code on a vulnerable server in the context of the SharePoint application pool account.
To exploit this vulnerability, an authenticated attacker would need to create a page specifically designed to cause a server-side request. The attacker would then send a specially-crafted message to perform a server-side request forgery attack.
The update addresses the vulnerability by modifying how Microsoft SharePoint Server manages server authentication.
FAQ: Is
GHSA
GHSA-fp4m-p3mj-5546: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request
ghsa_unreviewed·2022-05-24
CVE-2020-1178 [MEDIUM] CWE-269 GHSA-fp4m-p3mj-5546: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka 'Microsoft SharePoint Server Elevation of Privilege Vulnerability'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-09
Published